Payroll diversion fraud happens when an attacker changes the bank account used for an employee's salary. The request can arrive as a spoofed email, a compromised HR portal update or an impersonated employee phone call. Because payroll files are trusted bulk payments, one fraudulent change can bypass ordinary supplier controls unless payroll has its own verification process.
Treat a bank-detail change as a sensitive financial instruction
An employee can legitimately change banks, but payroll should not update the account from a plain email alone. Attackers who compromise a mailbox often send a convincing message shortly before payroll cut-off.
Use a secure HR self-service portal with MFA or an independent verification method. The employee's existing contact record should be the source for callback, not the new details supplied in the request.
Protect HR self-service from account takeover
If employees can edit their own bank details, require strong authentication and send an alert after every change. A payroll portal can be as financially sensitive as online banking because the next pay run sends money automatically.
High-risk changes can have a short cooling period or second-person review before they enter the payroll file.
Create a clear deadline for account changes
Last-minute requests on payroll day create pressure to bypass verification. Set a cutoff several days before file creation and require exceptional approval for later changes.
If a genuine employee misses the cutoff, paying the existing verified account can be safer than sending salary to an unverified new destination.
Run a changed-bank-details report before payroll approval
The payroll approver should see every employee whose account number or sort code changed since the last run. Compare the count with expected HR requests.
A payroll total can match perfectly while one employee's money goes to the wrong account, so beneficiary-change reporting is more important than aggregate control totals alone.
Review the first salary to a new account
For material or senior payroll, use Confirmation of Payee where the bank and workflow support it or another name-matching check. A mismatch should prompt investigation rather than automatic override.
Keep the verification evidence with the employee payroll record so the next audit can see why the change was accepted.
Contact the bank immediately after diversion is discovered
If salary went to a fraudulent account, contact the bank with payment reference, beneficiary and amount as soon as possible and preserve the fraudulent request.
Paying the employee correctly can be urgent, but the replacement payment should be linked to the failed or fraudulent first transaction so finance does not lose track of the recovery claim.
Worked example: a payroll employee receives an email from a director's compromised account requesting a new salary account one day before payroll. The email tone is normal and signature genuine. A callback to the director's known number reveals no change was requested, preventing the salary from being diverted.
Include payroll-bank changes in employee offboarding and rehire controls. Dormant employee profiles should not remain able to reactivate and change accounts without HR review.
Measure late change requests and verification failures. If the process generates too many emergencies, improve employee communication rather than weakening the control.
Worked example: payroll has 300 employees and seven bank-detail changes this month. Before file approval, the payroll manager reviews a change report showing each employee, old account, new account, verification method and verifier. One request has no completed verification and is removed from the file before submission.
Use employee self-service notifications to the old email or mobile channel where possible. If an attacker changes the account through a compromised portal, the genuine employee has another opportunity to report the change before payday.
Keep HR administrators from approving their own bank-detail changes. Insider and account-takeover risk both increase where one person can edit their payroll destination and release the change without another reviewer.
Analyse first-pay failures to new accounts. A high rate of rejected changes can indicate poor data validation and creates pressure for rushed manual replacement payments.
Use a payroll-file comparison that highlights changed sort codes and account numbers against the previous run. This is faster and more reliable than expecting an approver to notice one altered beneficiary inside hundreds of salary lines.
Keep replacement salary payments outside the normal file after a diversion incident. That makes the recovery, duplicate-payment risk and employee correction visible as one controlled exception.
Escalate repeated salary account changes by the same employee profile. Several changes in a short period can indicate account takeover or identity issues and should trigger stronger verification.
Keep payroll-change evidence for the same retention period as other payroll records where appropriate. Months later, finance should still be able to show who requested and verified the bank change.
Editorial Verdict
Payroll diversion fraud targets trusted recurring payments rather than the bank portal itself.
Verify account changes independently, review all changes before the payroll file is released and contact the bank quickly after any diversion. Salary data deserves beneficiary controls as strong as supplier data.
Sources
- National Cyber Security Centre, Business email compromise: https://www.ncsc.gov.uk/guidance/business-email-compromise
- National Cyber Security Centre, Phishing guidance: https://www.ncsc.gov.uk/guidance/phishing
- Pay.UK, Confirmation of Payee: https://www.wearepay.uk/what-we-do/overlay-services/confirmation-of-payee/